✨ AI Summary
The Governance, Risk & Compliance Senior Officer at Arab African International Bank will be responsible for assisting in IT and cybersecurity risk management processes, developing Information Security policies, and conducting security assessments. The role involves ensuring compliance with CBE standards, managing risk mitigation plans, and identifying potential IT and cybersecurity risks in new projects. Key responsibilities include performing GRC activities, proactive compliance risk management, and supporting the implementation of GRC platforms and security reports. The position requires a strong knowledge of information security policies, IT governance, risk, and compliance management, with 3-7 years of experience. Preferred certifications include CGRC, GRCP, CRISC, and ISO 27001. Familiarity with ISO 31000, ISO/IEC 38500, and NIST 800-30 is also beneficial. Excellent communication, analytical, and problem-solving skills are expected.
Requirements
Requires 3-7 years of experience in Information Security, IT governance, risk, and compliance management. Familiarity with GRC tools, Cyber security and IT Risk standards (ISO 27005), and regulatory standards (CBE, NIST, PCI-DSS) is essential. Excellent communication, analytical, and problem-solving skills are also required.
Description
KEY ACCOUNTABILITIESAssist in conducting the information technology and cybersecurity risk management processes and make sure there is ongoing risk reduction. Prepare the required Information Security policies to support AAIB s information Security governance and compliance objectives.Perform Cyber Security assessments on new and existing systems, processes, technology and ensure compliance with CBE and Security StandardWork with various AAIB business units to ensure Information Security controls are effectively implemented.Prepare information technology and cybersecurity risks mitigation plans, and periodically update risk register.Engage in new proposed projects to identify potential information technology and cybersecurity risks.Perform (governance, risk, and compliance) activities to ensure the implementation of security controls, exceptions, and risk mitigation.Ensure Compliance with CBE Conditional approvals related to information Security. Communicate with AAIB different teams for Proactive Compliance Risk Management - identification, assessment, risk action planning, and closures. Assist and share best practices for design and implementation of the GRC platforms.Support in preparing information security reports to track remediation activities and action plans.Identify Cyber Security and Information Technology risks in RCSAs and their related security controls for new and existing AAIB Projects/Products.Prepare and update Information Security Key Risk indicators QUALIFICATIONS, EXPERIENCE & SKILLSStrong knowledge in information Security policies and procedures developmentMinimum of 3 – 7 years of experience Good knowledge with IT governance, risk, and compliance management in a large global environmentPreferred certification: CGRC, GRCP, CRISC, ISO 27KGood Knowledge of ISO 31000's risk management principles; ISO/IEC 38500 (corporate governance of information technology)Familiarity with implementing and using GRC tools.Familiarity with Cyber security and IT Risk standards ISO 27005.Knowledge of Information Security management frameworks ex: NIST 800-30 and compliance practices.Strong knowledge in security assessment backgroundGood knowledge of compliance and regulatory standardsCBE standardsNIST standardsPCI-DSSSkills Excellent communication and leadership skills.Ability to handle high pressure situations with key stakeholders.Good Analytical skills, Problem solving and Interpersonal skills.Working knowledge and experience with MS office.